Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2002-01-31 CVE-2001-0891 Format string vulnerability in NQS daemon (nqsdaemon) in NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local user to gain root privileges by using qsub to submit a batch job whose name contains formatting characters.
local
low complexity
sgi cray
7.2
2002-01-30 CVE-2001-1457 Remote Security vulnerability in CrazyWWWBoard
Buffer overflow in CrazyWWWBoard 2000p4 and 2000LEp5 allows remote attackers to execute arbitrary code via a long HTTP_USER_AGENT CGI environment variable.
network
low complexity
nobreak-technologies
7.5
2002-01-13 CVE-2002-0077 Unspecified vulnerability in Microsoft Internet Explorer 5.0.1/5.5/6.0
Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the "Local Executable Invocation via Object tag" vulnerability.
network
low complexity
microsoft
7.5
2002-01-11 CVE-2003-0061 Local Security vulnerability in HP Hp-Ux 10.20
Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.
local
low complexity
hp
7.2
2002-01-02 CVE-2002-1594 Local Security vulnerability in Grpck
Buffer overflow in (1) grpck and (2) pwck, if installed setuid on a system as recommended in some AIX documentation, may allow local users to gain privileges via a long command line argument.
local
low complexity
grpck pwck
7.2
2001-12-31 CVE-2001-1584 Improper Input Validation vulnerability in Michael Barretto Cardboard 2.4
CardBoard 2.4 greeting card CGI by Michael Barretto allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient field.
network
low complexity
michael-barretto CWE-20
7.5
2001-12-31 CVE-2001-1582 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in SUN Solaris and Sunos
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary code via a long LDAP_OPTIONS environment variable to a privileged program that uses libsldap.
local
low complexity
sun CWE-119
7.2
2001-12-31 CVE-2001-1581 Security Bypass vulnerability in Clearswift Limited Mailsweeper 4.2
The File Blocker feature in Clearswift MAILsweeper for SMTP 4.2 allows remote attackers to bypass e-mail attachment filtering policies via a modified name in a Content-Type header.
network
low complexity
clearswift-limited
7.5
2001-12-31 CVE-2001-1577 Unspecified vulnerability in Caldera Openunix and Unixware
Unknown vulnerability in CDE in Caldera OpenUnix 7.1.0, 7.1.1, and 8.0 allows an xterm session to gain privileges when the session is reused.
network
low complexity
caldera
7.5
2001-12-31 CVE-2001-1572 Unspecified vulnerability in Linux Kernel
The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allows remote attackers to bypass packet filters via small packets.
network
low complexity
linux
7.5